#VU28463 Use of insufficiently random values in Spring Security - CVE-2020-5408
Published: June 1, 2020
Spring Security
VMware, Inc
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected software uses a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A remote authenticated attacker can derive the unencrypted values using a dictionary attack.